Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regist…
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager Broadc…
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 20…
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 20…
Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logg…
Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*…
Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in…
Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header,…
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`,…
The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious l…
Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL …
Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forger…
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API …
An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about …
Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOT…
Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log…
In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.